Live data from Hacker News

Tech firms seek to frustrate internet history log law

bbc.co.uk

131–140 of 170 posts

Re: Tech firms seek to frustrate internet history log law

#131

The problem with these systems is regardless of the efficacy, they are incredibly difficult to dismantle and easy to re-purpose with the stroke of a pen. And these "tech-savvy" people are dreaming if they think that access to VPN services from the UK will remain legal in the UK, esp. after a naughty person or two is shown to have used one to commission a crime. It won't happen quickly, but #include frog_boiling.h.

VPN isn't even that good of a protection anymore when all countries the traffic goes through log it and cooperate. VPN providers would have to introduce a random delay for their users, otherwise looking at all the exact times along the way gives a pretty good idea who accesses what.

Not if your VPN is outside the UK surely?

Re: Tech firms seek to frustrate internet history log law

#132
post #100
post #66

Earlier quoted context omitted.

> they will have to outlaw inability to decrypt. The UK's already done that - the Regulation of Investigatory Powers Act 2000 already made it an offence not to divulge encryption keys when asked. [1] 1 https://wiki.openrightsgroup.org/wiki/Regulation_of_Investig...

Yes, that's a step towards it. But at least the person has to be a "suspect" in another crime (however low the bar for that is) and an explicit demand has to be made for the key. Not that it does a lot of good since anybody can become a suspect and the demand for the key is retrospective to when you weren't a suspect.

https://www.youtube.com/watch?v=BO8EpfyCG2Y (Constable Savage)

Suspect of being Muslim, wearing a beard and using an ISP that the public hasn't heard of that isn't price competitive is more than enough for a media hatchet job. How low does the bar have to be?

This should be the preserve of Uganda and N Korea.

Re: Tech firms seek to frustrate internet history log law

#133
post #129

> "Terrorists and serious criminals will always seek to avoid detection." So, if you don't want the government to see your thoughts, you're a criminal.

No, that's confusing A->B with B->A. All dogs are mammals, but not all mammals are dogs.

Re: Tech firms seek to frustrate internet history log law

#134
post #53

The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…

The US has at least one mechanism against that: the first amendment. Content and format are both matters of speech, so the choice of format and the decision to broadcast noise as a statement are both protected. I expect that will come under attack, but it's a very fundamental part of US law used unambiguously. So we might also see civil war 2 before they get that legally changed.

They'll get around it on a technicality. Just like NSA did with the 4th Amendment. "Yeah, sure we capture US citizens' data, but we don't do it on US soil and use another moniker (GCHQ) so its ok. Not our fault AT&T routed your call outside of constitutional jurisdiction!".

I'm expecting something like, "Yeah, sure you can have your 1st amendment, you just have to give us the keys if we ask or you get charged with destroying evidence/obstruction of justice which together carry more time than almost whatever possible illegal activity your encrypted traffic could have been concealing.

Re: Tech firms seek to frustrate internet history log law

#135
post #53

The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…

This may be a stupid question but I've got to ask because I'm not 100% sure. Is there no practical way data can be sent and received anonymously? If no one, except the people trying to communicate, knows who encrypted or decrypted anything, how could they enforce such a law? Since a well encrypted message should be safe to broadcast, it can be sent to the whole world with only the intended recipients being able to de…

because when you send messages, they go from your computer to your ISP, then to the internet. so anyone watching you at the ISP level sees you sent something.

Then, it depends where you sent it. Email goes to one person, so receipt of the message is seen on their ISP's side.

Yes the encrypted message is safe to be sent to the whole world, but there is no single public folder for "the whole world". That would be too many files. In order for the receiver to find what they wanted, they would have to browse the public folder to find what they needed, and this act of browsing strips the anonymity away.

The other problem is that you have to exchange the decryption keys with the person you intend to communicate with. You either need to physically give/mail them to the recipient (loss of anonymity in the case of mail), or else you need to exchange them electronically, which usually requires an AB exchange, or you can post your public key and let the recipient find it.

Basically, if you are a government watching all the communication from above, you can usually tell what path information takes, even if its posted publicly.

Re: Tech firms seek to frustrate internet history log law

#136
post #53

The logical end point, if you think it through, is scary for technology. There will be a battle for a time where legislators play cat and mouse with technology and privacy companies. But as each new hole appears, they'll invent new laws to close them off. This wouldn't be so bad except for the problem that encryption is math and short of making math illegal there will always be a hole. Factor in steganography and it…

> Software development, already dominated by tech behemoths, will become completely out of reach of small development teams simply because the regulatory burden is so high.

It might sound OT to bring up TPP in a discussion like this, but please hear me out: It's important to block broad international agreements like TPP because it creates competition among nations that would protect us from the dystopia you describe.

Let's say one nation, Uruguay, says "you know what ? Encryption is fine. And btw we're funding 1gb cheap fiber to everyone in our biggest city". Something like that could attract swarms of techies. Which would cause larger nations to think twice before their valued tech talent packs up and moves to escape their surveillance state.

I know not everyone can pack up and go, but the competition and fear of just how many might leave would be enough to keep even rich nations in check. But if something like TPP goes though, they can point to all its provisions and say "boo hoo, you're shitting on trade deals by allowing encryption, now we're going to bully your whole nation with economic sanctions"

Re: Tech firms seek to frustrate internet history log law

#137
post #25

Earlier quoted context omitted.

Well, if memory serves, for the most part haven't most terrorist attacks been coordinated over either completely open channels or over non-technical channels? If I remember correctly, the Bin Laden operations were orchestrated via sneakernet, the more recent attacks in France were orchestrated with check-out aisle cell phones. The technical difficulties law enforcement faces with terrorism and crime isn't that crimin…

> Well, if memory serves, for the most part haven't most terrorist attacks been coordinated over either completely open channels or over non-technical channels? If I remember correctly, the Bin Laden operations were orchestrated via sneakernet, the more recent attacks in France were orchestrated with check-out aisle cell phones. We have no way of knowing. There hasn't been a repeat attack at the scale of 9/11 to date…

[deleted]

Re: Tech firms seek to frustrate internet history log law

#138
Having visited England recently, despite the surveillance engine being prepped in the US, the contrast of the extent and the lack of rights and legal means in the UK to protect the people from bad laws like this was palpable. So look at it this way, at least you don't live there.

If we keep headed in the same direction though it won't be long before we forget all the reasons for the American Revolution and let the globalists convince us to rejoin the empire cough the commonwealth again.

Of course, any American who advocates for such a thing is traitorous, and should have the full weight of the law brought down on them.

I don't know, maybe I'm crazy and I'm the only one who thinks oaths mean anything these days.

I will say this though, beware the Rhodesians and their round tables.

Re: Tech firms seek to frustrate internet history log law

#139
post #59

Earlier quoted context omitted.

> All my encrypted traffic to my overseas based VPN will be logged (legal). Then you'll demand my keys so that you can decrypt it. If the VPN connection uses ephemeral keys (IIRC, at least IPSEC, SSH, and TLS 1.3 always use ephemeral keys, while older TLS uses them when possible), by then it's too late: the keys are gone.

You can imagine someone being locked up for this though. If you are required by law to decrypt your data, and you chose technology that does not allow this, then that's on you. To use an analogy, if you choose to ride a bike that doesn't have lights, and then get pulled over for riding without lights, the lack of lights is not a defense because you were required to have them in order to be on the road at night.

The law as written protects you against this:

RIPA S49(2) (http://www.legislation.gov.uk/ukpga/2000/23/part/III/crosshe...):

If any person with the appropriate permission under Schedule 2 believes, on reasonable grounds—

(a)that a key to the protected information is in the possession of any person,

(b)that the imposition of a disclosure requirement in respect of the protected information is—

(i)necessary on grounds falling within subsection (3), or

(ii)necessary for the purpose of securing the effective exercise or proper performance by any public authority of any statutory power or statutory duty,

(c)that the imposition of such a requirement is proportionate to what is sought to be achieved by its imposition, and

(d)that it is not reasonably practicable for the person with the appropriate permission to obtain possession of the protected information in an intelligible form without the giving of a notice under this section,

the person with that permission may, by notice to the person whom he believes to have possession of the key, impose a disclosure requirement in respect of the protected information.

If the technology by implementation never gives you the keys and doesn't retain them, then there can't be a reasonable belief that you're in possession of the keys, so the requirement fails at the first hurdle.

Re: Tech firms seek to frustrate internet history log law

#140

Earlier quoted context omitted.

This may be a stupid question but I've got to ask because I'm not 100% sure. Is there no practical way data can be sent and received anonymously? If no one, except the people trying to communicate, knows who encrypted or decrypted anything, how could they enforce such a law? Since a well encrypted message should be safe to broadcast, it can be sent to the whole world with only the intended recipients being able to de…

because when you send messages, they go from your computer to your ISP, then to the internet. so anyone watching you at the ISP level sees you sent something. Then, it depends where you sent it. Email goes to one person, so receipt of the message is seen on their ISP's side. Yes the encrypted message is safe to be sent to the whole world, but there is no single public folder for "the whole world". That would be too m…

Yes the encrypted message is safe to be sent to the whole world, but there is no single public folder for "the whole world". That would be too many files.

I think USENET and nntp came really close to fulfilling most of "single public folder for the whole world", but unfortunately has fallen out of popular use (and it needs to be popular enough to increase the anonymity) because it wasn't walled-garden enough to make money from.

Post reply on HN